Summary
bin/pytorch_inference/Main.cc keeps TERMINATE_ON_DEGRADED_SECCOMP_FAILURE at false so legacy-route launches still run when in-process seccomp BPF cannot be installed.
Hard termination becomes safe only once every production launch carries an explicit --disableSandbox or --requireSandbox token (Elasticsearch already does on Linux via PyTorchBuilder).
Acceptance
- Flip the constant (or wire it to a controller guarantee) once the no-token legacy default is no longer reachable for production callers.
- Verify degraded launches fail closed when seccomp cannot install.
Related: #3188
Summary
bin/pytorch_inference/Main.cckeepsTERMINATE_ON_DEGRADED_SECCOMP_FAILUREatfalseso legacy-route launches still run when in-process seccomp BPF cannot be installed.Hard termination becomes safe only once every production launch carries an explicit
--disableSandboxor--requireSandboxtoken (Elasticsearch already does on Linux viaPyTorchBuilder).Acceptance
Related: #3188